AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company wants workload deployments to access Azure resources without storing client secrets in CI/CD variables. The pipeline runs from GitHub Actions. Which identity design should be used?
⚠ Common exam trap
Test-takers frequently choose a long-lived client secret (Option D) thinking it is the standard way to authenticate, overlooking the requirement to avoid storing secrets and the modern OIDC-based federation approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Workload identity federation with Microsoft Entra ID
Workload identity federation with Microsoft Entra ID allows GitHub Actions to exchange an OpenID Connect (OIDC) token for an Azure access token, eliminating the need to store client secrets in CI/CD variables. This design uses short-lived tokens and federated identity credentials, aligning with the principle of zero-trust and secretless authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A shared user account with MFA disabled
Why it's wrong here
Using a shared user account with MFA disabled is a classic anti-pattern: user identities are designed for interactive human login, not automated workloads, and a shared account provides no accountability for individual actions. Because no MFA protects the account, a single leaked password gives total access, and replicating that shared credential into deployment pipelines increases the blast radius. Workload identity federation instead uses a distinct non-human identity that is trusted without static credentials and can be scoped with granular permissions.
- ✗
A storage account access key
Why it's wrong here
A storage account access key authenticates only against Azure Blob/File/Queue/Table data planes, so it cannot obtain OAuth tokens for Microsoft Entra ID-protected services such as Microsoft Graph, ARM, or Key Vault data plane. The key is an all-powerful, long-lived shared secret that grants full access to the storage account (including key management), making rotating and securing it a major operational burden. Even for storage scenarios, managed identities or Entra roles should be preferred; for general workload access, a workload identity federation token is required.
- ✓
Workload identity federation with Microsoft Entra ID
Why this is correct
Workload identity federation with Microsoft Entra ID lets an external workload (for example, a GitHub Actions job or a Kubernetes pod) present a token from its own trusted identity provider to Entra ID in exchange for an Entra access token. This uses OAuth 2.0 client credentials grant flow with no client secret, because the federated credential defines trust by issuer, subject, and audience. The resulting short-lived tokens can be scoped to Azure resources or Microsoft Graph, eliminating long-lived secrets and enabling automated rotation through the source identity provider.
- ✗
A long-lived app registration client secret
Why it's wrong here
An app registration client secret, even one with a long expiration, is a static shared secret that must be stored in code, build scripts, or vaults; anyone who extracts it can authenticate as the service principal until it expires or is rotated. Long-lived secrets are operationally risky because rotation is often forgotten, and unlike workload identity federation, they are not tied to an ephemeral source token from the workload's own provider. While service principal secrets can technically request Entra tokens, they are an outdated pattern that fails to provide the zero-lifetime-secret benefit of federated workload identity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.